Icepick
Topic Starter
I'm having a problem where ads are appearing in the bottom left corner of nearly every webpage I visit, nearly all of them linking to ads.yieldmanager.com. I'm also getting the occasional random direct to another webpage - this has only happened a couple of times, but I only really noticed the problem in the last day or so.
I've run scans with ad-aware, Avast, Malware Bytes and TDSS Killer, and none of these have found anything.
One of the posts in the help section said I should run DDS and paste the log, so here it is - any help is greatly appreciated!
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16457
Run by [removed] at 19:57:33 on 2013-01-03
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.44.1033.18.16291.12780 [GMT 0:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Lavasoft Ad-Aware *Disabled/Updated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Lavasoft Ad-Aware *Disabled/Updated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}
FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\IProsetMonitor.exe
C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Windows\system\ComHookMonitor.exe
C:\Program Files\ASUS Xonar D2 Audio\Customapp\ASUSAUDIOCENTER.EXE
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
C:\Users\Icepick\Local Settings\Apps\F.lux\flux.exe
C:\Users\Icepick\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\CyberLink\Shared files\brs.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~2\AD-AWA~1\AdAware.exe
C:\Program Files (x86)\mIRC\mirc.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Opera\opera.exe
C:\Windows\explorer.exe
C:\Program Files (x86)\Ipswitch\WS_FTP 12\WsftpCOMHelper.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: DivX Plus Web Player HTML5 : {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: CIESpeechBHO Class: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [Power2GoExpress] NA
uRun: [NCsoft]
mRun: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
mRun: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
mRun: [UpdatePDRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\7.0"
mRun: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
mRun: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
mRun: [UpdatePPShortCut] "C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0"
mRun: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Blu-ray Disc Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Ad-Aware Browsing Protection] "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"
mRun: [Ad-Aware Antivirus] "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" –windows-run
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
StartupFolder: C:\Users\Icepick\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Icepick\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\Icepick\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Trillian.lnk - C:\Program Files (x86)\Trillian\trillian.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: NameServer = 192.168.2.1
TCP: Interfaces\{D0F9571C-7E02-4430-BD61-73454653C404} : DHCPNameServer = 192.168.2.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
SSODL: WebCheck -
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
x64-Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
x64-Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
x64-Run: [Cmaudio8788] C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.cpl,CMICtrlWnd
x64-Run: [Cmaudio8788Hook] C:\Windows\system\ComHookMonitor.exe
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} -
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck -
Hosts: 199.193.118.246 www.google-analytics.com.
Hosts: 199.193.118.246 ad-emea.doubleclick.net.
Hosts: 199.193.118.246 www.statcounter.com.
Hosts: 199.193.118.246 connect.facebook.net.
Hosts: 93.115.241.27 www.google-analytics.com.
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
============= SERVICES / DRIVERS ===============
.
R0 gfibto;gfibto;C:\Windows\System32\drivers\gfibto.sys [2013-1-3 14456]
R0 mv91cons;Marvell 91xx Config Device Driver;C:\Windows\System32\drivers\mv91cons.sys [2011-3-14 24880]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-1-3 984144]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-1-3 370288]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2011/09/10 19:34:34];C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [2010-2-24 146928]
R2 Ad-Aware Service;Ad-Aware Service;C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [2012-12-14 1236968]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-1-3 25232]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-1-3 71600]
R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2011-3-13 74912]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-1-3 44808]
R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;C:\Windows\System32\IPROSetMonitor.exe [2011-8-21 164520]
R2 SBAMSvc;Ad-Aware;C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [2012-9-20 3677000]
R2 sbapifs;sbapifs;C:\Windows\System32\drivers\sbapifs.sys [2012-9-12 82872]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-2 382824]
R3 AthBTPort;Atheros Virtual Bluetooth Class;C:\Windows\System32\drivers\btath_flt.sys [2011-3-13 36000]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\System32\drivers\btath_a2dp.sys [2011-3-13 298656]
R3 BTATH_BUS;Atheros Bluetooth Bus;C:\Windows\System32\drivers\btath_bus.sys [2011-3-13 28832]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\System32\drivers\btath_hcrp.sys [2011-3-13 201376]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\System32\drivers\btath_lwflt.sys [2011-3-13 55456]
R3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\System32\drivers\btath_rcp.sys [2011-3-13 154272]
R3 BtFilter;BtFilter;C:\Windows\System32\drivers\btfilter.sys [2011-3-13 280224]
R3 cmudaxp;ASUS Xonar D2 Audio Interface;C:\Windows\System32\drivers\cmudaxp.sys [2011-9-10 1161216]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-8-21 317440]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-12-10 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-12-10 181248]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-8-21 452200]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-9 160944]
S3 ATHDFU;Atheros Valkyrie USB BootROM;C:\Windows\System32\drivers\AthDfu.sys [2011-3-13 51872]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-21 20992]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\System32\drivers\Synth3dVsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\System32\drivers\terminpt.sys [2010-11-21 34816]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 tsusbhub;tsusbhub;C:\Windows\System32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-5-10 51712]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-8-22 1255736]
.
=============== Created Last 30 ================
.
2013-01-03 19:36:09 ——– d—–w- C:\Users\Icepick\AppData\Roaming\Malwarebytes
2013-01-03 19:36:00 ——– d—–w- C:\ProgramData\Malwarebytes
2013-01-03 19:35:59 24176 —-a-w- C:\Windows\System32\drivers\mbam.sys
2013-01-03 19:35:59 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-01-03 19:32:48 ——– d—–w- C:\Users\Icepick\AppData\Local\Programs
2013-01-03 18:58:19 ——– d—–w- C:\ProgramData\Ad-Aware Antivirus
2013-01-03 18:57:08 ——– d—–w- C:\Users\Icepick\AppData\Roaming\LavasoftStatistics
2013-01-03 18:49:03 984144 —-a-w- C:\Windows\System32\drivers\aswSnx.sys
2013-01-03 18:49:03 71600 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2013-01-03 18:49:03 54072 —-a-w- C:\Windows\System32\drivers\aswRdr2.sys
2013-01-03 18:48:56 41224 —-a-w- C:\Windows\avastSS.scr
2013-01-03 18:48:49 ——– d—–w- C:\ProgramData\AVAST Software
2013-01-03 18:48:49 ——– d—–w- C:\Program Files\AVAST Software
2013-01-03 18:46:19 ——– d—–w- C:\Program Files (x86)\Ad-Aware Antivirus
2013-01-03 18:46:12 ——– d—–w- C:\Users\Icepick\AppData\Local\Downloaded Installations
2013-01-03 18:46:11 47496 —-a-w- C:\Windows\System32\sbbd.exe
2013-01-03 18:46:11 14456 —-a-w- C:\Windows\System32\drivers\gfibto.sys
2013-01-03 18:44:12 ——– d—–w- C:\ProgramData\blekko toolbars
2013-01-03 18:44:10 ——– d—–w- C:\Users\Icepick\AppData\Local\adawarebp
2013-01-03 18:44:09 ——– d—–w- C:\ProgramData\Ad-Aware Browsing Protection
2013-01-03 18:44:06 ——– d—–w- C:\Program Files (x86)\adawaretb
2013-01-03 18:44:04 ——– d—–w- C:\Program Files (x86)\Toolbar Cleaner
2013-01-03 18:42:44 ——– d—–w- C:\Users\Icepick\AppData\Roaming\Ad-Aware Antivirus
2013-01-02 00:35:30 9125352 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3B7422F6-4D7E-41B6-849D-4D72FAB6237F}\mpengine.dll
2013-01-01 20:24:26 ——– d—–w- C:\Users\Icepick\AppData\Local\{79FAF880-46D9-426D-B103-6ED5D1144571}
2012-12-27 19:43:00 ——– d—–w- C:\Users\Icepick\AppData\Local\{72E822EA-14AE-48EF-BBD7-739828CDBFBC}
2012-12-22 03:01:18 46080 —-a-w- C:\Windows\System32\atmlib.dll
2012-12-22 03:01:18 367616 —-a-w- C:\Windows\System32\atmfd.dll
2012-12-22 03:01:18 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll
2012-12-22 03:01:18 295424 —-a-w- C:\Windows\SysWow64\atmfd.dll
2012-12-20 09:55:16 ——– d—–w- C:\Users\Icepick\AppData\Local\{EDC34CD7-74EE-4BFB-B1D5-AF52CBDBA8BA}
2012-12-16 20:44:36 ——– d—–w- C:\Users\Icepick\AppData\Local\{7398B953-2964-49FA-83B4-849A40214C52}
2012-12-13 18:22:28 ——– d—–w- C:\Users\Icepick\AppData\Local\{8CC2E226-FC02-48EC-9264-D518621FAF71}
2012-12-13 09:28:59 887296 —-a-w- C:\Program Files\Internet Explorer\iedvtool.dll
2012-12-13 09:28:59 678912 —-a-w- C:\Program Files (x86)\Internet Explorer\iedvtool.dll
2012-12-13 09:28:59 499200 —-a-w- C:\Program Files\Internet Explorer\jsdbgui.dll
2012-12-13 09:28:59 387584 —-a-w- C:\Program Files (x86)\Internet Explorer\jsdbgui.dll
2012-12-11 21:04:14 33240 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2012-12-11 21:04:11 ——– d—–w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-12-11 21:04:11 ——– d—–w- C:\Program Files\iTunes
2012-12-11 21:04:11 ——– d—–w- C:\Program Files\iPod
2012-12-11 21:04:11 ——– d—–w- C:\Program Files (x86)\iTunes
2012-12-09 17:01:48 ——– d—–w- C:\Users\Icepick\AppData\Local\{00AC25ED-9CE8-4003-8C63-8AAC179367A7}
2012-12-09 16:55:58 ——– d—–w- C:\Users\Icepick\AppData\Roaming\ftblauncher
2012-12-09 00:08:54 ——– d—–w- C:\Users\Icepick\AppData\Local\{A953133B-1B2D-47EA-9CDC-A783DABB54A2}
2012-12-06 17:15:45 ——– d—–w- C:\Users\Icepick\AppData\Local\{6F64AC04-860D-4AF8-B4A0-B9814859F729}
2012-12-05 22:44:48 ——– d—–w- C:\Users\Icepick\AppData\Local\{EC0ABABE-7D5E-4DFF-AAF2-FBC9D73149DC}
2012-12-04 22:17:55 ——– d—–w- C:\Users\Icepick\AppData\Local\{AD34F7C5-E8FA-4D68-9AF7-DD6330763C34}
.
==================== Find3M ====================
.
2012-12-12 00:05:32 73656 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-12-12 00:05:32 697272 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-11-22 03:26:40 3149824 —-a-w- C:\Windows\System32\win32k.sys
2012-11-14 06:11:44 2312704 —-a-w- C:\Windows\System32\jscript9.dll
2012-11-14 06:04:11 1392128 —-a-w- C:\Windows\System32\wininet.dll
2012-11-14 06:02:49 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl
2012-11-14 05:57:46 599040 —-a-w- C:\Windows\System32\vbscript.dll
2012-11-14 05:57:35 173056 —-a-w- C:\Windows\System32\ieUnatt.exe
2012-11-14 05:52:40 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2012-11-14 02:09:22 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll
2012-11-14 01:58:15 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-11-14 01:57:37 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll
2012-11-14 01:49:25 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-11-14 01:48:27 420864 —-a-w- C:\Windows\SysWow64\vbscript.dll
2012-11-14 01:44:42 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2012-11-13 20:29:04 354216 —-a-w- C:\Windows\SysWow64\DivXControlPanelApplet.cpl
2012-11-09 05:45:09 2048 —-a-w- C:\Windows\System32\tzres.dll
2012-11-09 04:42:49 2048 —-a-w- C:\Windows\SysWow64\tzres.dll
2012-11-02 05:59:11 478208 —-a-w- C:\Windows\System32\dpnet.dll
2012-11-02 05:11:31 376832 —-a-w- C:\Windows\SysWow64\dpnet.dll
2012-10-25 03:12:26 94208 —-a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2012-10-25 03:12:26 69632 —-a-w- C:\Windows\SysWow64\QuickTime.qts
2012-10-16 08:38:37 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38:34 350208 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39:52 561664 —-a-w- C:\Windows\apppatch\AcLayers.dll
2012-10-10 21:22:54 2428776 —-a-w- C:\Windows\SysWow64\nvapi.dll
2012-10-10 21:22:52 26331496 —-a-w- C:\Windows\System32\nvoglv64.dll
2012-10-10 21:22:52 1760104 —-a-w- C:\Windows\System32\nvdispco64.dll
2012-10-10 21:22:32 15309160 —-a-w- C:\Windows\SysWow64\nvd3dum.dll
2012-10-10 21:22:26 2747240 —-a-w- C:\Windows\System32\nvcuvid.dll
2012-10-10 21:22:24 19906920 —-a-w- C:\Windows\SysWow64\nvoglv32.dll
2012-10-10 21:22:18 13443944 —-a-w- C:\Windows\System32\drivers\nvlddmkm.sys
2012-10-10 21:22:14 17559912 —-a-w- C:\Windows\SysWow64\nvcompiler.dll
2012-10-09 18:17:13 55296 —-a-w- C:\Windows\System32\dhcpcsvc6.dll
2012-10-09 18:17:13 226816 —-a-w- C:\Windows\System32\dhcpcore6.dll
2012-10-09 17:40:31 44032 —-a-w- C:\Windows\SysWow64\dhcpcsvc6.dll
2012-10-09 17:40:31 193536 —-a-w- C:\Windows\SysWow64\dhcpcore6.dll
.
============= FINISH: 19:57:42.85 ===============